|
213761
|
6.1 |
MEDIUM
Network
|
altn
|
mdaemon
|
MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 2 of 2).
|
CWE-79
Cross-site Scripting
|
CVE-2019-8984
|
2024-11-21 13:50 |
2019-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213762
|
6.1 |
MEDIUM
Network
|
altn
|
mdaemon
|
MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 1 of 2).
|
CWE-79
Cross-site Scripting
|
CVE-2019-8983
|
2024-11-21 13:50 |
2019-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213763
|
9.6 |
CRITICAL
Network
|
wavemaker
|
wavemarker_studio
|
com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-8982
|
2024-11-21 13:50 |
2019-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213764
|
7.5 |
HIGH
Network
|
linux canonical opensuse debian
|
linux_kernel ubuntu_linux leap debian_linux
|
A memory leak in the kernel_read_file function in fs/exec.c in the Linux kernel through 4.20.11 allows attackers to cause a denial of service (memory consumption) by triggering vfs_read failures.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-8980
|
2024-11-21 13:50 |
2019-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213765
|
9.8 |
CRITICAL
Network
|
kohanaframework
|
kohana
|
Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled.
|
CWE-89
SQL Injection
|
CVE-2019-8979
|
2024-11-21 13:50 |
2019-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213766
|
8.8 |
HIGH
Network
|
indexhibit
|
indexhibit
|
In Indexhibit 2.1.5, remote attackers can execute arbitrary code via the v parameter (in conjunction with the id parameter) in a upd_jxcode=true action to the ndxzstudio/?a=system URI.
|
CWE-20
Improper Input Validation
|
CVE-2019-8954
|
2024-11-21 13:50 |
2019-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213767
|
6.1 |
MEDIUM
Network
|
netgate
|
haproxy
|
The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.php and haproxy_listeners_edit.php.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8953
|
2024-11-21 13:50 |
2019-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213768
|
9.8 |
CRITICAL
Network
|
dasannetworks
|
h665_firmware
|
The backdoor account dnsekakf2$$ in /bin/login on DASAN H665 devices with firmware 1.46p1-0028 allows an attacker to login to the admin account via TELNET.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-8950
|
2024-11-21 13:50 |
2019-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213769
|
9.8 |
CRITICAL
Network
|
papercut
|
papercut_mf papercut_ng
|
PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163.
|
CWE-74
Injection
|
CVE-2019-8948
|
2024-11-21 13:50 |
2019-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213770
|
6.5 |
MEDIUM
Network
|
octopus
|
octopus_deploy octopus_server
|
An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variab…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-8944
|
2024-11-21 13:50 |
2019-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|